Modifying Cisco AnyConnect Split Tunnel via Group Policy
An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generated by the user is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goal?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests knowledge of where split-tunneling exclusions are defined in Cisco ASA/FTD configurations, specifically distinguishing between NAT rules and group policies.
This page explains how to configure split tunneling for a remote access VPN on Cisco Secure Firewall (FTD) and Cisco AnyConnect clients by modifying the group policy.
Engineers often mistakenly look for 'NAT exemption' or 'routing table' modifications to exclude traffic, but these do not control which traffic enters the tunnel versus the local network.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To exclude specific servers from a remote access VPN tunnel so they are accessed directly via the internet, you must enable and configure split tunneling. On Cisco ASA and FTD devices running AnyConnect, split tunneling settings—including the list of excluded networks—are contained within the Group Policy object. Modifying this policy allows the engineer to define the exclusion list effectively.Why the Other Options Are Wrong
NAT exemption prevents translation but does not control routing decisions regarding the tunnel interface; it simply ensures traffic isn't translated when it matches a rule. The encryption domain defines what traffic initiates the IPsec phase 1 negotiation (usually site-to-site), not client traffic flows. The routing table determines path selection but cannot be easily modified dynamically per-client without complex static routes; Group Policy is the intended mechanism for client-side routing instructions.Community Comment Notes
Community consensus strongly supports Group Policy as the correct answer. Users noted that "split tunneling is indeed located under group policy settings" and referenced the configuration path: Configuration > Remote Access VPN > Group Policies. This aligns with standard Cisco AnyConnect deployment practices.Exam Strategy
When configuring remote access VPNs, always check the Group Policy for client-specific behaviors like split tunneling and DNS settings before looking at global firewall rules or NAT configurations.
Frequently Asked Questions
Where is split tunneling configured in FTD?
Split tunneling and exclusion lists are configured within the Group Policy object under the Advanced settings for Remote Access VPN.
Does NAT exemption stop traffic from going through the tunnel?
No, NAT exemption only prevents address translation. It does not determine whether traffic enters the VPN tunnel or exits locally; Group Policy controls that.